Skip to main content
AI-powered endpoint enrichment and analysis for IT security - Tanium Tech Talks #162 video thumbnail
Module Deep Dive

AI-powered endpoint enrichment and analysis for IT security - Tanium Tech Talks #162

Tanium HuntIQ Hunter Duncan Miller demonstrates how AI-powered enrichment and analysis features inside Threat Response are transforming the way security teams decode commands, contextualize alerts, and act on findings, all without leaving the console.

Investigating a security alert has always required analysts to move fast while carrying a lot of context in their heads: understanding what an encoded PowerShell command is doing, why an alert fired, what the surrounding process ancestry means, and what to do next. For junior analysts, that context takes years to build. For senior analysts, even deep experience doesn't cover every edge case. The result, as many security teams report, is slower investigations, lower analyst confidence, and constrained team capacity. The AI-powered enrichment and analysis features inside Tanium Threat Response are designed to close that gap directly inside the workflow where investigations actually happen.


Duncan walks through two new capabilities in Threat Response: command-line enrichment and alert analysis. The enrichment feature decodes encoded commands and breaks down every component of a command line, explaining what each parameter does and flagging security implications in plain language. The Analyze feature goes further, taking an entire alert as context and returning a structured summary that includes why the alert fired, key findings, an impact assessment, and recommended actions.

If you've ever lost your investigative thread by switching windows to look up what a command line means, or struggled to explain to a junior analyst why a specific alert should concern them, this episode covers exactly the capabilities that address those problems. Watch the full walkthrough in the video below.

Key takeaways

  • Enrich decodes and explains: The Enrich button inside an alert doesn't just decode an encoded PowerShell command. It breaks down every component of the command line, explains what each parameter does, and surfaces security implications such as "Frequently used in malicious context to evade policy-based controls."
  • Non-standard cmdlets get flagged: When the enrichment encounters something like get-uac, it identifies that it is not a built-in cmdlet and likely a custom function, and recommends investigating the source and preceding activity for potential staging.
  • Alert Analyze provides full context: The Analyze feature takes the entire alert as context, including process ancestry, command lines, and intel details, and returns an initial alert overview explaining exactly why the alert fired, key findings highlighting unusual elements, an impact assessment, and recommended actions.
Because if I have to leave here and go ask an LLM, look in Google to see what this particular command line means, I'm leaving here and I'm increasing my chances of losing my context for when I come back, right? So what was I looking at? What was the thing before this? What were the things after this I was planning on doing? I'm trying to keep all of that straight while I'm leaving the console to go someplace else. Keeping the context within the console lets you keep your focus and not have to re-remember what you were trying to do beforehand, so I find it amazingly helpful.
Tanium HuntIQ Hunter Duncan Miller
  • Recommended actions require environmental context: Duncan notes that while the recommended actions are sensible, such as isolating the endpoint, terminating and quarantining the SQL in Users splunkd, and blocking outbound traffic to the associated domain, they must be contextualized within the environment. Isolating a key domain controller or a revenue-generating machine without that context could create serious problems.
  • Enrichment extends to direct connections and data grids: The same enrichment capability available in alerts is also present in direct connections and within the data grid. Anywhere the sparkles appear, analysts can enrich a command line for additional context, including browser command lines from Chrome or Edge that are otherwise difficult to interpret.
I would say look for the sparkles and if you see the sparkles, you can get more context around it.
Tanium HuntIQ Hunter Duncan Miller
  • Availability requires Threat Response, cloud, and AI features enabled: These features are currently available at no additional charge to customers who are licensed for Threat Response, are cloud customers, and have AI features enabled in their environment.

Additional resources